216.73.217.22

DeedRAT: Unpacking a Modern Backdoor's Playbook

· Published 31/12/2025 22:59 · Modified 02/01/2026 11:02

Export JSON

Essential information

Published
31/12/2025 22:59
Modified
02/01/2026 11:02
Tags
2025-12-31 apt backdoor deedrat dll sideloading phishing
Related entities
4 observables, 1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 4 others

Description

is a sophisticated associated with the Chinese group Salt Typhoon, targeting critical sectors globally. It infiltrates systems through campaigns, utilizing to evade detection. The malware establishes persistence via registry run keys and service creation, ensuring long-term access. 's capabilities include file manipulation, system reconnaissance, and payload execution. The infection chain involves three files: a legitimate executable, a malicious DLL, and an encrypted file. Once installed, it attempts to connect to its command-and-control server. Defensive measures include monitoring email traffic, registry changes, and anomalous service creations.

External references